Description
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.
Remediation
References
Related Vulnerabilities
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-30130)
WebLogic CVE-2023-21842 Vulnerability (CVE-2023-21842)
phpMyAdmin Other Vulnerability (CVE-2006-3388)
PHP Other Vulnerability (CVE-2007-1378)
Atlassian Jira CVE-2021-26076 Vulnerability (CVE-2021-26076)